Legal
Personal data processing
What this site collects, why, who sees it on the way, and how it is protected. This document describes what actually happens and is updated together with the site.
In force from 1 August 2026
1. Who processes the data
The controller is Надир Абдурахманов, author and owner of autonoma.uk. Processing follows the UK GDPR and the EU GDPR, and Russian Federal Law No. 152-FZ where it applies.
To raise any question about your data, use the form on this site or write to the controller: the address appears in your browser.
2. What is collected
Only what you type into the enquiry form yourself:
- the name you give;
- one contact of your choice — email or a messenger handle;
- the direction of work and the budget range you select;
- the description of your task.
A separate technical record notes that an enquiry happened — direction, budget range and timestamp. It is anonymous: no name, no contact, no text, and it cannot identify a person. Its only purpose is counting enquiries.
3. Purpose and legal basis
There is one purpose: replying to you and discussing the work. The legal basis is your consent, given by ticking the box before you submit. Consent is voluntary and can be withdrawn at any time.
The data is never used for mailings, passed to third parties for advertising, sold, or fed into automated decision-making.
4. Who is involved in delivery
Enquiries pass through services acting as processors on the controller’s instructions; they may not use the data for their own purposes:
| Service | Role | Servers |
|---|---|---|
| Web3Forms | delivers the enquiry to the controller’s mailbox | USA |
| Telegram | mirrors the enquiry to the controller’s direct messages | UAE |
| Cloudflare | domain DNS and the relay that forwards enquiries | USA |
| GitHub Pages | stores and serves the site’s pages | USA |
Nobody else receives your data except where the law requires it. There are no subcontractors with access to it.
5. International transfers
As the table shows, the processors’ servers sit outside the UK and the EEA, so submitting the form involves an international transfer. By sending the form you agree to it. If that does not suit you, write to the controller directly by email or messenger instead — then your data never passes through these services.
6. How long data is kept
- correspondence — while the discussion and the project are live, then no more than three years;
- the anonymous enquiry record — the last thousand entries, older ones drop out automatically;
- on your request, correspondence is deleted sooner — within thirty days.
7. How the data is protected
This site is built by an engineer rather than assembled in a site builder, so the measures are named specifically rather than in general terms:
Less data is collected than possible
The form asks for no phone, no company, no job title — a name, one contact and the description of the task. What is not collected cannot leak.
The site has no database
It is static: pages are served as files, there is no server-side storage and no admin panel. Nothing lingers on the site to be stolen.
The enquiry counter is anonymous
Statistics keep only the direction, the budget range and the timestamp. No name, no contact, no task text — the log cannot identify a person.
Keys live apart from the code
The site’s code is public, but tokens and keys are not in it: they sit in encrypted secret storage. Every commit is checked for leaked credentials.
Transport is HTTPS only
The site and the relay run over TLS; plain HTTP is redirected to the secure version.
The relay accepts only its own site
Enquiries are accepted from this site’s addresses only, and the service channel is signed with a secret key. Requests from other origins are rejected unprocessed.
Mailbox and messenger are protected
The accounts that receive enquiries are secured with unique passwords and two-factor authentication.
No analytics, no ad trackers
No Analytics, no pixels, no ad networks. No tracking cookies, no profiling — the site does not follow its visitors.
Absolute security does not exist, and promising it would be a lie. What is listed closes the ordinary leak paths for a site this size: no storage, minimal data, keys kept apart from code, encrypted transport.
8. If a breach happens
If an incident affects your data, the controller notifies the supervisory authority within the statutory deadline and tells you directly when you are affected: what happened, which data was involved and what has been done. No silence, no “we handled it quietly”.
9. Your rights
At any time you may:
- ask what data is held about you and where it came from;
- have inaccurate data corrected;
- withdraw consent and ask for erasure;
- receive a copy of your data;
- complain to a supervisory authority — in the UK, the Information Commissioner’s Office.
Send the request through the form or by email. Response and erasure within thirty days, usually sooner.
10. Changes
This document is updated whenever the site or its services change. The current version always lives at this address, with the effective date at the top. The edit history is public: the site is published from an open repository, so every change to this text is visible there.